VRRP group remains master on both NE40E routers

Publication Date: 2013-04-01Views: 81Downloads: 0

Issue Description

VRRP group remains master on both NE40E routers, while NE40E-1 is configured to be the MASTER and NE40E-2 backup. Both routers are running under version NE40E&80E V600R001C00SPCe00 and connection between routers are made by two S9300 switches, according to the following topology:

No alarm information were shown on display logbuffer, display trapbuffer or display alarm all, however, if command display vrrp command was run on both routers, we could see that they were working as MASTER at the same time:

Due the port security configuration, virtual MAC address was being handled as a secured MAC address and not being released by the switches. Since Virtual MAC address has to "float" between both routers, this configuration was avoiding this behavior.

Solution

Delete port security configured on uplink interfaces.

Suggestions

For this kind of topology, port security configuration on uplink interfaces is not suggested.